When you get a message from the CEO or an urgent request from the founder, you want to respond fast. It’s very normal not to want to pause and ask questions when you receive instructions from someone in a key leadership role at work.
Threat actors understand the psychology behind that dynamic – and they make use of it.
Recent research from Outtake analysed 43,035 executive impersonation alerts involving 270 executives across its monitored customer sample during 2025 and 2026. Its central finding is that executive impersonation is playing out more often across the open internet, where corporate security teams have limited visibility.
Fake social-media profiles accounted for 53.83% of alerts, while fake accounts on video platforms contributed another 35.06%. Together, those two surfaces represented almost nine out of ten alerts in Outtake's sample.
It’s a concentration that makes sense – because social platforms give impersonators direct access to customers and other people who already recognise an executive's name. Video accounts add another layer of credibility, allowing attackers to circulate fabricated endorsements, investment pitches and cryptocurrency giveaways under that executive's identity.
The tactic scales because the trust already exists. Attackers simply borrow it.
From fake profiles to fake authority
Public information can provide the starting material for an impersonation campaign.
Outtake found that open forums, broker sites and exposed personal data can provide raw material for later impersonation, fraud, credential theft and blackmail. From there, a fake profile can send direct messages; a lookalike domain can support convincing emails; and a video account can distribute the same scam to a wide audience in just a few hours.
Outtake’s researchers recorded 1,537 alerts involving executive-lookalike domains. These domains and sites can appear legitimate and support emails that look as though they came from the executive or their office.
Interestingly, different leaders attract different forms of impersonation. Outtake associates:
- Fake social profiles with founders and public-facing CEOs
- Video impersonation with founders and public spokespeople.
- Board chairs and executives involved in active matters may appear in open forums, while financial-services and investor-relations leaders can become attractive identities for domain-based impersonation.
As Outtake puts it: "Every executive is targeted differently."
And that makes executive protection a contextual challenge. Monitoring an executive's email domain alone leaves a wide field of social accounts, video platforms, forums and lookalike domains outside the picture.
Attackers only need a short window
Speed guides the economics of executive impersonation. Outtake describes a window between publication and removal in which a fake account can contact customers, request a wire transfer or pose as an executive in conversations with board members:
"The attacker doesn't need the fake to last forever, just long enough."
And AI increases the value of that window. According to the report, it allows threat actors to launch impersonation campaigns in minutes – creating a significant speed advantage over manual detection and takedown processes.
A recent report on fraud and security trends from Infobip adds broader context here. It recorded a 94% year-on-year increase in phishing volume across its platform, with phishing accounting for 49% of blocked harmful content during 2025.
Researchers also observed 628% growth in AI-powered image detection, which Infobip links to fraudsters hiding harmful content inside images to bypass text-based filters.
Executive impersonation fits naturally into that landscape. Video gives a fake endorsement rapid reach, while image-based content can evade controls that rely heavily on text analysis.
What should organisations prioritise?
Executive impersonation is a problem at the intersection of cybersecurity, fraud, and reputation management.
Security teams need visibility across social platforms, video services and lookalike domains. Finance teams benefit from clear verification processes for payment requests. Executives and board members benefit from agreed communication channels for sensitive instructions, supported by independent verification whenever money, credentials or confidential information are involved.
The threat succeeds by combining trust and urgency into a single message.
So building resilience starts by creating enough friction for someone to pause, verify the request, and ask: is the boss really on the other side?
Learn from the leading minds in cybersecurity and build resilience for your organisation at Black Hat MEA 2026.